论文标题
演示:btlemap:蓝牙低能的nmap
DEMO: BTLEmap: Nmap for Bluetooth Low Energy
论文作者
论文摘要
蓝牙低能设备的市场正在蓬勃发展,同时,已经成为对手的有吸引力的目标。为了提高总体安全性,我们提出了BTLEMAP,这是一个针对BLE环境的审计应用程序。 BTLEMAP的灵感来自网络发现和安全审核工具,例如基于IP的网络的NMAP。它允许设备枚举,GATT服务发现和设备指纹打印。通过集成BLE广告解剖器,数据出口商和用户友好的UI(包括接近视图),它更进一步。 BTLEMAP当前使用Apple的CoreBluetooth API在iOS和MACO上运行,但也接受替代数据输入(例如Raspberry Pi)来克服受限制的供应商API。开源项目正在积极开发中,并将提供更高级的功能,例如将来的长期设备跟踪(尽管MAC地址随机化)。
The market for Bluetooth Low Energy devices is booming and, at the same time, has become an attractive target for adversaries. To improve BLE security at large, we present BTLEmap, an auditing application for BLE environments. BTLEmap is inspired by network discovery and security auditing tools such as Nmap for IP-based networks. It allows for device enumeration, GATT service discovery, and device fingerprinting. It goes even further by integrating a BLE advertisement dissector, data exporter, and a user-friendly UI, including a proximity view. BTLEmap currently runs on iOS and macOS using Apple's CoreBluetooth API but also accepts alternative data inputs such as a Raspberry Pi to overcome the restricted vendor API. The open-source project is under active development and will provide more advanced capabilities such as long-term device tracking (in spite of MAC address randomization) in the future.